Impact
The vulnerability is a heap‑based buffer overflow in the Windows Encrypting File System (EFS). An authenticated local attacker can trigger the overflow to execute arbitrary code with elevated privileges, enabling full local privilege escalation. This issue maps to CWE‑122, which indicates a heap corruption that may allow attackers to subvert application logic and gain access. The practical effect is that any logged‑on user who can run code and has the ability to manipulate EFS data could potentially elevate to administrator level and compromise system integrity, confidentiality, and availability.
Affected Systems
Affected Windows releases include Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and all supported Windows Server editions from 2012 through 2025, including both full and Server Core installations. Each of these operating systems contains the vulnerable EFS implementation that the overflow targets. The list of affected models is provided by Microsoft and matches the CPE strings shown in the advisory.
Risk and Exploitability
The CVSS score of 7.8 marks the flaw as high severity, but the EPSS metric is currently unavailable, so the probability of exploitation cannot be quantified. Microsoft has not listed it in their KEV catalog, suggesting no publicly known exploits at this time. The exploitation requires a local, authorized user with sufficient privileges to influence EFS behavior, implying that remote attack vectors are unlikely. In the absence of a public exploit, the overall risk is moderate to high for environments that rely on EFS and have privileged users; the threat becomes significant if users routinely run untrusted code or use elevation rights.
OpenCVE Enrichment